Junglewise Threat Intelligence

CVE-2026-49800: Microsoft Windows integer overflow in WPAD service

CVE-2026-49800 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2022, Microsoft Windows 10, Microsoft Windows Server 2019, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Windows component responsible for automatically discovering web proxy settings. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

This vulnerability is characterized as an integer overflow or wraparound (CWE-190) leading to a heap-based buffer overflow (CWE-122) within the Windows Web Proxy Auto-Discovery (WPAD) service. The flaw is triggered during the processing of WPAD responses. An attacker with local access and low-level privileges can exploit this by sending specially crafted data to the service, resulting in memory corruption. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue across affected Windows and Windows Server versions.

Affected products

  • Microsoft Windows 10 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2019 All versions
  • Microsoft Windows Server 2022 All versions

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via Microsoft Security Update Guide.

References

Related threats